**Link to problem area**: https://spec.matrix.org/unstable/rooms/v11/#authorization-rules **Issue** We should have: > Add auth rule: “If any auth event has a `room_id` which doesn’t match our `room_id`, reject”. Synapse [implements](https://github.com/element-hq/synapse/blob/9d43bec/synapse/event_auth.py#L234) this already, but it should be clarified in the spec.